MALICIOUS — de7aba66a81777eeb4e074e81704b55ec08a2dd69b2a10ba588285cb75de616a
MALICIOUS — de7aba66a81777eeb4e074e81704b55ec08a2dd69b2a10ba588285cb75de616a is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Mydoom family. 7 of 52 detection engines flagged it, exhibiting 3 ATT&CK techniques.
Identification
- SHA-256:
de7aba66a81777eeb4e074e81704b55ec08a2dd69b2a10ba588285cb75de616a - SHA-1:
9cfa2a16a6813a762ecb6fe268e92562de6c4f3c - MD5:
0f9a34734c78f9fe3205750141b26fa7 - imphash:
3a226e5a32d54c9874ff46ff138d22cb - ssdeep:
384:1vxBbK26lj5Id8SpHx9jLhsznnVxA1WmP5w7GGCJlqqwMyNRQA:Dv8IRRdsxq1DjJcqfIr - TLSH:
T1CE2DE09441603CA3C5B39A819C444B7CE1524F3110AA29CCDE13B0661BFE6EFE3B1262 - Submitted as: de7aba66a81777eeb4e074e81704b55ec08a2dd69b2a10ba588285cb75de616a
- File type: pe · Size: 28864 bytes
- Verdict: malicious (100/100) · Family: Mydoom
Detections (7 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Mydoom-90
- Detect It Easy (packer/type): DIE:UPX 1.24
- Microsoft Defender: Worm:Win32/Mydoom.O@mm
- Emsisoft (Emergency Kit): Worm.Generic.24461
- Trellix Stinger (McAfee): Obfuscated-FGB!hb
- Kaspersky (KVRT): Email-Worm.Win32.Mydoom.m
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Worm.Mydoom-90 (rule
Win.Worm.Mydoom-90) - engine signal, weight 0.90, confidence 0.95 - Dropped a malicious payload (Mydoom): ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9 - dynamic signal, weight 0.80, confidence 0.90
- Microsoft Defender flagged Worm:Win32/Mydoom.O@mm (rule
Worm:Win32/Mydoom.O@mm) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Worm.Generic.24461 (rule
Worm.Generic.24461) - engine signal, weight 0.55, confidence 0.85 - Trellix Stinger (McAfee) flagged Obfuscated-FGB!hb (rule
Obfuscated-FGB!hb) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Email-Worm.Win32.Mydoom.m (rule
Email-Worm.Win32.Mydoom.m) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 55 external host(s) at runtime (47 HTTP) - network signal, weight 0.40, confidence 0.80
- Detect It Easy (packer/type) flagged DIE:UPX 1.24 (rule
DIE:UPX 1.24) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1, UPX 1.24 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
5839 behavior events · 2 ATT&CK techniques · 12 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- lists.freedesktop.org
- gabe.freedesktop.org
- global.libreoffice.org
- documentfoundation.org
- libreoffice.org
- vm194.documentfoundation.org
- mail.documentfoundation.org
- mx3.heinlein-support.de
- search.yahoo.com
- search.lycos.com
Dropped files
- /opt/CAPEv2/storage/analyses/20309/files/ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9 -
ebbf9b45ed59430a486d17d916cfb647e20eec494488622bcac94e47a098bfb9 - /opt/CAPEv2/storage/analyses/20309/files/3e4ecdfbd4a54ebd6297c3f00996d25ba582d2bbc5364402ed21268c4ceac46b -
3e4ecdfbd4a54ebd6297c3f00996d25ba582d2bbc5364402ed21268c4ceac46b - /opt/CAPEv2/storage/analyses/20309/files/9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb -
9e26c61078335ede1fe8e9463e075b149b45ea829f24be32faa594708ea620cb - /opt/CAPEv2/storage/analyses/20309/files/e753a9079d18870ae22f0aea9d9c61ecd88ec70685cbc02fe980bfe050c5edef -
e753a9079d18870ae22f0aea9d9c61ecd88ec70685cbc02fe980bfe050c5edef - /opt/CAPEv2/storage/analyses/20309/files/e8549ecfdc4641a35f78f536c081e72c38b3fbde86679a810902c4f7090db00a -
e8549ecfdc4641a35f78f536c081e72c38b3fbde86679a810902c4f7090db00a - /opt/CAPEv2/storage/analyses/20309/files/ec9e7a3d898703e68775405093261c4adf90811bb9c0a70c0ad135c70ebc8d2c -
ec9e7a3d898703e68775405093261c4adf90811bb9c0a70c0ad135c70ebc8d2c - /opt/CAPEv2/storage/analyses/20309/files/bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c -
bf316f51d0c345d61eaee3940791b64e81f676e3bca42bad61073227bee6653c - /opt/CAPEv2/storage/analyses/20309/files/6aa63394c1f5e705b1e89c55ff19eed71957e735c3831a845ff62f74824e13f1 -
6aa63394c1f5e705b1e89c55ff19eed71957e735c3831a845ff62f74824e13f1 - /opt/CAPEv2/storage/analyses/20309/files/6f41c4b0fa819a30404c07d21dd2be71360b98573bfea57ba713a5e5e8b83d07 -
6f41c4b0fa819a30404c07d21dd2be71360b98573bfea57ba713a5e5e8b83d07 - /opt/CAPEv2/storage/analyses/20309/files/7f55442bb7a1a86e81e0f9518194c30c77c9bb75209032d31d725a2add450690 -
7f55442bb7a1a86e81e0f9518194c30c77c9bb75209032d31d725a2add450690 - /opt/CAPEv2/storage/analyses/20309/files/5d133d5d24eba8d27a86f1c4cab46ac685afac888cf9584f0c93696be0e9b1e2 -
5d133d5d24eba8d27a86f1c4cab46ac685afac888cf9584f0c93696be0e9b1e2 - /opt/CAPEv2/storage/analyses/20309/files/f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666 -
f2a831e1e3f3a2f8696fb13f3c0c0d181889c729e9c8ba7555d4f8477cf60666
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/2cbcf400-ac8d-4d86-9d69-c7f0dff56d2e?P1=1786771286&P2=404&P3=2&P4=cIimfAa%2bz8hX9%2f1NKzh6MydcTqd6w5Xnw3mfp%2fka%2bjNRrg5t45a2GoZWZjeg33vSVjnmiRWVjC%2fOdI1YMbaErQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://search.yahoo.com/search?p=mailto+lists.freedesktop.org&ei=UTF-8&fr=fp-tab-web-t&cop=mss&tab=
- http://search.yahoo.com/search?p=mailto+libreoffice.org&ei=UTF-8&fr=fp-tab-web-t&cop=mss&tab=&n=100
- http://search.yahoo.com/search?p=email+lists.freedesktop.org&ei=UTF-8&fr=fp-tab-web-t&cop=mss&tab=&n=100
- http://www.altavista.com/web/results?q=contact+e-mail+global.libreoffice.org&kgs=0&kls=0&nbq=20
- http://www.altavista.com/web/results?q=mailto+lists.freedesktop.org&kgs=0&kls=0&nbq=50
- http://www.altavista.com/web/results?q=mailto+documentfoundation.org&kgs=0&kls=0&nbq=50
- http://www.altavista.com/web/results?q=contact+mail+documentfoundation.org&kgs=0&kls=0&nbq=50
- http://www.altavista.com/web/results?q=mailto+lists.freedesktop.org&kgs=0&kls=0&nbq=20
Embedded domains
- global.libreoffice.org
- documentfoundation.org
- libreoffice.org
- mail.documentfoundation.org
- vm194.documentfoundation.org
- mx3.heinlein-support.de
- search.yahoo.com
- search.lycos.com
- www.altavista.com
- au.search.yahoo.com
Embedded IP addresses
- 52.182.141.63
- 4.230.171.124
- 85.210.196.11
- 4.144.132.114
- 52.253.84.76
- 74.179.77.204
- 4.150.223.102
- 20.165.94.63
- 74.179.77.164
- 135.233.45.221
- 20.42.73.27
- 15.96.48.12
- 16.202.85.155
- 52.123.252.247
- 72.145.35.99
- 16.188.146.5
- 162.159.142.9
- 52.123.128.14
- 20.236.44.162
- 135.232.92.34
- 203.26.79.13
- 131.252.210.177
- 88.99.190.237
- 89.238.68.194
- 91.198.250.30
More Mydoom samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report